<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic MAB, Apple-device profile in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/mab-apple-device-profile/m-p/3775392#M541912</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;How are you profiling OS-X devices for MAB in your place?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;While working in ISE 2.4(patch 3), found out if you spoof the mac-address of Macbook Pro Ethernet dangle which mine start with mac (68:5b:35) to match of one of Cisco provided profiles that is OUI(mac-address prefix) based or a profile you created that is OUI based, then that Macbook pro profiled as that device and not as Apple-device which is a huge issue for me, because guest apple OS-X devices should be getting guest access and not the full access that assigned to the profiles (my environment is a testing environment for now) , i'm using cisco provided apple-device profiles without any changes&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I will demonstrate Crestron-device which is profile Cisco provided profile based on device OUI so if the mac-address prefix start with 00:10:7F then they profiled Crestron-device.&lt;/P&gt;
&lt;P&gt;1- allowed crestron to get full access to the network or any level access ,assuming that we have it in production and need to access internal resources, its done via policy set if endpoint policy=crestron device&lt;/P&gt;
&lt;P&gt;2- changed my macbook pro mac address to 00:10:7F:00:12:34 with command sudo ifconfig en3 ether 00:10:7F:00:12:34&lt;/P&gt;
&lt;P&gt;2- started endpoint debug&lt;/P&gt;
&lt;P&gt;3- no shutdown the access port&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;dhcp probe&lt;/P&gt;
&lt;P&gt;MAC: 00:10:7F:00:12:34&lt;BR /&gt;Attribute:BYODRegistration value:Unknown&lt;BR /&gt;Attribute:DeviceRegistrationStatus value:NotRegistered&lt;BR /&gt;Attribute:EndPointPolicy value:Unknown&lt;BR /&gt;Attribute:EndPointPolicyID value:&lt;BR /&gt;&lt;STRONG&gt;Attribute:EndPointSource value:DHCP Probe&lt;/STRONG&gt;&lt;BR /&gt;Attribute:IdentityGroup value:&lt;BR /&gt;Attribute:IdentityGroupID value:&lt;BR /&gt;Attribute:MACAddress value:00:10:7F:00:12:34&lt;BR /&gt;Attribute:MatchedPolicy value:Unknown&lt;BR /&gt;Attribute:MatchedPolicyID value:&lt;BR /&gt;Attribute:NmapSubnetScanID value:0&lt;BR /&gt;&lt;STRONG&gt;Attribute:OUI value:CRESTRON ELECTRONICS, INC.&lt;/STRONG&gt;&lt;BR /&gt;Attribute:PolicyVersion value:0&lt;BR /&gt;Attribute:PortalUser value:&lt;BR /&gt;Attribute:PostureApplicable value:Yes&lt;BR /&gt;Attribute:StaticAssignment value:false&lt;BR /&gt;Attribute:StaticGroupAssignment value:false&lt;BR /&gt;Attribute:Total Certainty Factor value:0&lt;BR /&gt;Attribute:chaddr value:00:10:7f:00:12:34&lt;BR /&gt;Attribute:ciaddr value:0.0.0.0&lt;BR /&gt;Attribute:dhcp-client-identifier value:01:00:10:7f:00:12:34&lt;BR /&gt;Attribute:dhcp-lease-time value:7776000&lt;BR /&gt;Attribute:dhcp-max-message-size value:1500&lt;BR /&gt;Attribute:dhcp-message-type value:DHCPREQUEST&lt;BR /&gt;&lt;STRONG&gt;Attribute:dhcp-parameter-request-list value:1, 121, 3, 6, 15, 119, 252, 95, 44, 46&lt;/STRONG&gt;&lt;BR /&gt;Attribute:dhcp-requested-address value:10.101.234.27&lt;BR /&gt;Attribute:flags value:0x0000&lt;BR /&gt;Attribute:giaddr value:10.101.234.1&lt;BR /&gt;Attribute:hlen value:6&lt;BR /&gt;Attribute:hops value:1&lt;BR /&gt;Attribute:host-name value:Mustafas-MBP&lt;BR /&gt;Attribute:htype value:Ethernet (10Mb)&lt;BR /&gt;Attribute:ip value:10.101.234.27&lt;BR /&gt;Attribute:op value:BOOTREQUEST&lt;BR /&gt;Attribute:secs value:0&lt;BR /&gt;Attribute:tranID value:0x94a74c38&lt;BR /&gt;Attribute:yiaddr value:0.0.0.0&lt;BR /&gt;Attribute:SkipProfiling value:false&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;results:&lt;/P&gt;
&lt;P&gt;Attribute:AAA-Server value:SNS-PSN1&lt;BR /&gt;Attribute:AcsSessionID value:SNS-PSN1/334707989/1080&lt;BR /&gt;Attribute:AuthenticationIdentityStore value:Internal Endpoints&lt;BR /&gt;Attribute:AuthenticationMethod value:Lookup&lt;BR /&gt;Attribute:AuthenticationStatus value:AuthenticationPassed&lt;BR /&gt;Attribute:&lt;STRONG&gt;AuthorizationPolicyMatchedRule value:SNS DATA&lt;/STRONG&gt;&lt;BR /&gt;Attribute:BYODRegistration value:Unknown&lt;BR /&gt;Attribute:CPMSessionID value:0A65EA050000103942F963D8&lt;BR /&gt;Attribute:Called-Station-ID value:E0-D1-73-8E-FA-84&lt;BR /&gt;Attribute:Calling-Station-ID value:00-10-7F-00-12-34&lt;BR /&gt;Attribute:DTLSSupport value:Unknown&lt;BR /&gt;Attribute:DestinationIPAddress value:10.155.76.89&lt;BR /&gt;Attribute:DestinationPort value:1812&lt;BR /&gt;Attribute:Device IP Address value:switch ip removed&lt;BR /&gt;Attribute:Device Type value:Device Type#switch type removed&lt;BR /&gt;Attribute:DeviceRegistrationStatus value:notRegistered&lt;BR /&gt;Attribute:EndPointMACAddress value:00-10-7F-00-12-34&lt;BR /&gt;&lt;STRONG&gt;Attribute:EndPointMatchedProfile value:Crestron-Device&lt;/STRONG&gt;&lt;BR /&gt;Attribute:EndPointPolicy value:211fce40-8c00-11e6-996c-525400b48521&lt;BR /&gt;Attribute:EndPointPolicyID value:&lt;BR /&gt;Attribute:EndPointSource value:RADIUS Probe&lt;BR /&gt;Attribute:FailureReason value:-&lt;BR /&gt;Attribute:Framed-IP-Address value:10.101.234.27&lt;BR /&gt;Attribute:Framed-MTU value:1500&lt;BR /&gt;Attribute:IPSEC value:IPSEC#Is IPSEC Device#No&lt;BR /&gt;Attribute:ISEPolicySetName value:WIRED_MAB&lt;BR /&gt;Attribute:IdentityGroup value:&lt;BR /&gt;Attribute:IdentityGroupID value:&lt;BR /&gt;Attribute:IdentityPolicyMatchedRule value:INTERNAL_AUTHEN&lt;BR /&gt;Attribute:IdentitySelectionMatchedRule value:INTERNAL_AUTHEN&lt;BR /&gt;Attribute:IsThirdPartyDeviceFlow value:false&lt;BR /&gt;Attribute:Location value:Location#location removed&lt;BR /&gt;Attribute:MACAddress value:00:10:7F:00:12:34&lt;BR /&gt;Attribute:MatchedPolicy value:Unknown&lt;BR /&gt;Attribute:MatchedPolicyID value:&lt;BR /&gt;Attribute:MessageCode value:5200&lt;BR /&gt;Attribute:NAS-IP-Address value:switch ip removed&lt;BR /&gt;Attribute:NAS-Port value:50104&lt;BR /&gt;Attribute:NAS-Port-Id value:GigabitEthernet1/0/4&lt;BR /&gt;Attribute:NAS-Port-Type value:Ethernet&lt;BR /&gt;&lt;STRONG&gt;Attribute:Name value:Endpoint Identity Groups:Profiled&lt;/STRONG&gt;&lt;BR /&gt;Attribute:Network Device Profile value:Cisco&lt;BR /&gt;Attribute:NetworkDeviceGroups value:Location#location removed, Device Type#switch type removed, IPSEC#Is IPSEC Device#No&lt;BR /&gt;Attribute:NetworkDeviceName value:Mustafa_ISE_3850&lt;BR /&gt;Attribute:NetworkDeviceProfileId value:b0699505-3150-4215-a80e-6753d45bf56c&lt;BR /&gt;Attribute:NetworkDeviceProfileName value:Cisco&lt;BR /&gt;Attribute:NmapSubnetScanID value:0&lt;BR /&gt;&lt;STRONG&gt;Attribute:OUI value:CRESTRON ELECTRONICS, INC.&lt;/STRONG&gt;&lt;BR /&gt;Attribute:OriginalUserName value:00107f001234&lt;BR /&gt;Attribute:PolicyVersion value:0&lt;BR /&gt;Attribute:PortalUser value:&lt;BR /&gt;Attribute:PostureApplicable value:Yes&lt;BR /&gt;Attribute:PostureAssessmentStatus value:NotApplicable&lt;BR /&gt;Attribute:RadiusFlowType value:WiredMAB&lt;BR /&gt;Attribute:RequestLatency value:40&lt;BR /&gt;Attribute:Response value:{UserName=00:10:7F:00:12:34; User-Name=00-10-7F-00-12-34; State=ReauthSession:0A65EA050000103942F963D8; Class=CACS:0A65EA050000103942F963D8:SNS-PSN1/334707989/1080; cisco-av-pair=ACS:CiscoSecure-Defined-ACL=#ACSACL#-IP-PERMIT-ALL-TRAFFIC-5c088efb; cisco-av-pair=profile-name=Crestron-Device; LicenseTypes=1539; }&lt;BR /&gt;Attribute:SSID value:E0-D1-73-8E-FA-84&lt;BR /&gt;Attribute:SelectedAccessService value:SNS-PROTOCOLS&lt;BR /&gt;Attribute:SelectedAuthenticationIdentityStores value:Internal Endpoints&lt;BR /&gt;&lt;STRONG&gt;Attribute:SelectedAuthorizationProfiles value:Full Access&lt;/STRONG&gt;&lt;BR /&gt;Attribute:Service-Type value:Call Check&lt;BR /&gt;Attribute:StaticAssignment value:false&lt;BR /&gt;Attribute:StaticGroupAssignment value:false&lt;BR /&gt;Attribute:StepData value:5= Normalised Radius.RadiusFlowType, 7=Internal Endpoints, 14= EndPoints.EndPointPolicy&lt;BR /&gt;Attribute:Total Certainty Factor value:0&lt;BR /&gt;Attribute:UseCase value:Host Lookup&lt;BR /&gt;Attribute:User-Name value:00107f001234&lt;BR /&gt;Attribute:UserName value:00-10-7F-00-12-34&lt;BR /&gt;Attribute:UserType value:Host&lt;BR /&gt;Attribute:allowEasyWiredSession value:false&lt;BR /&gt;Attribute:cisco-av-pair value:service-type=Call Check, audit-session-id=0A65EA050000103942F963D8, method=mab&lt;BR /&gt;Attribute:ip value:10.101.234.27&lt;BR /&gt;Attribute:SkipProfiling value:false&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;as you can see the OUI is Crestron and its getting that access level which is full in my case,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the only attribute from apple OSX (client side) is the dhcp-parameter-request-list value:1, 121, 3, 6, 15, 119, 252, 95, 44, 46 so i went ahead and and modify apple-device profile to check for this value and to increase the certainty by 20 to override the crestron certainty of 5.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is the result&lt;/P&gt;
&lt;P&gt;MAC: 00:10:7F:00:12:34&lt;BR /&gt;Attribute:AAA-Server value:SNS-PSN1&lt;BR /&gt;Attribute:AuthenticationIdentityStore value:Internal Endpoints&lt;BR /&gt;Attribute:AuthenticationMethod value:Lookup&lt;BR /&gt;&lt;STRONG&gt;Attribute:AuthorizationPolicyMatchedRule value:NON-SNS-APPLE_NON-SNS-USER(GUEST)&lt;/STRONG&gt;&lt;BR /&gt;Attribute:BYODRegistration value:Unknown&lt;BR /&gt;Attribute:CacheUpdateTime value:1546972431455&lt;BR /&gt;Attribute:Calling-Station-ID value:00-10-7F-00-12-34&lt;BR /&gt;Attribute:CreateTime value:1546972400212&lt;BR /&gt;Attribute:DTLSSupport value:Unknown&lt;BR /&gt;Attribute:DestinationIPAddress value:10.150.67.89&lt;BR /&gt;Attribute:Device Identifier value:&lt;BR /&gt;Attribute:Device Type value:Device Type#switch type removed&lt;BR /&gt;Attribute:DeviceRegistrationStatus value:NotRegistered&lt;BR /&gt;&lt;STRONG&gt;Attribute:EndPointPolicy value:Apple-MacBook&lt;/STRONG&gt;&lt;BR /&gt;Attribute:EndPointPolicyID value:09c71730-8c00-11e6-996c-525400b48521&lt;BR /&gt;Attribute:EndPointProfilerServer value:SNS-PSN1.my.place.net&lt;BR /&gt;Attribute:EndPointSource value:RADIUS Probe&lt;BR /&gt;Attribute:FailureReason value:-&lt;BR /&gt;Attribute:FirstCollection value:1546972399878&lt;BR /&gt;Attribute:Framed-IP-Address value:10.101.234.27&lt;BR /&gt;Attribute:IdentityGroup value:Profiled&lt;BR /&gt;Attribute:IdentityGroupID value:aa10ae00-8bff-11e6-996c-525400b48521&lt;BR /&gt;Attribute:LastActivity value:1546972430885&lt;BR /&gt;Attribute:LastNmapScanTime value:0&lt;BR /&gt;Attribute:Location value:Location#location removed&lt;BR /&gt;Attribute:MACAddress value:00:10:7F:00:12:34&lt;BR /&gt;Attribute:MDMServerID value:&lt;BR /&gt;&lt;STRONG&gt;Attribute:MatchedPolicy value:Apple-MacBook&lt;/STRONG&gt;&lt;BR /&gt;Attribute:MatchedPolicyID value:09c71730-8c00-11e6-996c-525400b48521&lt;BR /&gt;Attribute:MessageCode value:3000&lt;BR /&gt;Attribute:NAS-IP-Address value:10.101.234.5&lt;BR /&gt;Attribute:NAS-Port-Id value:GigabitEthernet1/0/4&lt;BR /&gt;Attribute:NAS-Port-Type value:Ethernet&lt;BR /&gt;Attribute:NetworkDeviceName value:Mustafa_ISE_3850&lt;BR /&gt;Attribute:NmapScanCount value:0&lt;BR /&gt;Attribute:NmapSubnetScanID value:0&lt;BR /&gt;&lt;STRONG&gt;Attribute:OUI value:CRESTRON ELECTRONICS, INC.&lt;/STRONG&gt;&lt;BR /&gt;Attribute:PhoneID value:&lt;BR /&gt;Attribute:PolicyVersion value:12&lt;BR /&gt;Attribute:PortalUser value:&lt;BR /&gt;Attribute:PostureApplicable value:Yes&lt;BR /&gt;Attribute:RegistrationTimeStamp value:0&lt;BR /&gt;Attribute:SSID value:E0-D1-73-8E-FA-84&lt;BR /&gt;&lt;STRONG&gt;Attribute:SelectedAuthorizationProfiles value:SNS GUEST&lt;/STRONG&gt;&lt;BR /&gt;Attribute:StaticAssignment value:false&lt;BR /&gt;Attribute:StaticGroupAssignment value:false&lt;BR /&gt;Attribute:TimeToProfile value:315&lt;BR /&gt;Attribute:Total Certainty Factor value:30&lt;BR /&gt;Attribute:UniqueSubjectID value:&lt;BR /&gt;Attribute:UpdateTime value:0&lt;BR /&gt;Attribute:User-Name value:00107f001234&lt;BR /&gt;Attribute:UserName value:00-10-7F-00-12-34&lt;BR /&gt;Attribute:UserType value:Host&lt;BR /&gt;Attribute:ciaddr value:0.0.0.0&lt;BR /&gt;Attribute:dhcp-parameter-request-list value:1, 121, 3, 6, 15, 119, 252, 95, 44, 46&lt;BR /&gt;Attribute:dhcp-requested-address value:10.101.234.27&lt;BR /&gt;Attribute:host-name value:Mustafas-MBP&lt;BR /&gt;Attribute:ip value:10.101.234.27&lt;BR /&gt;Attribute:SkipProfiling value:false&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;from the results we saw OS-X profiled successfully as as apple-device regardless of the user's mac spoofing attempt, Cisco released Parameter Request List Value&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/116235-configure-ise-00.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/116235-configure-ise-00.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;but my macbook Parameter wasn't part of the list, it look like the list is dated&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;now i have few questions&lt;/P&gt;
&lt;P&gt;- will this attribute change or vary from model/OS release to another? if yes, how can we make sure we have the latest Parameter? where it can be found Cisco ISE doc or Apple site?&lt;/P&gt;
&lt;P&gt;- is there any other attribute we can count on that is hard solid and will never change?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;please understand those macbook devices belongs to the guests so i cant install any clients/application on them and we dont have access to&amp;nbsp;their hostname, OS-X version nor model, and for crestron and other profile which i'm not willing to modify to accommodate the apple-devices because the number of profiles are big and not sure if/when Cisco will update one of their provided profile, looking for solution from apple-device profile side.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;FYI: This is not an issue with Windows as windows have many attributes that ISE capture, so changing mac addresses wont matter(if you are using the default profiles) and no changes, no sure and about linux but its in the scope after apple-devices issue resolved.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Mustafa&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 08:53:38 GMT</pubDate>
    <dc:creator>mustafa83</dc:creator>
    <dc:date>2019-03-11T08:53:38Z</dc:date>
    <item>
      <title>MAB, Apple-device profile</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-apple-device-profile/m-p/3775392#M541912</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;How are you profiling OS-X devices for MAB in your place?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;While working in ISE 2.4(patch 3), found out if you spoof the mac-address of Macbook Pro Ethernet dangle which mine start with mac (68:5b:35) to match of one of Cisco provided profiles that is OUI(mac-address prefix) based or a profile you created that is OUI based, then that Macbook pro profiled as that device and not as Apple-device which is a huge issue for me, because guest apple OS-X devices should be getting guest access and not the full access that assigned to the profiles (my environment is a testing environment for now) , i'm using cisco provided apple-device profiles without any changes&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I will demonstrate Crestron-device which is profile Cisco provided profile based on device OUI so if the mac-address prefix start with 00:10:7F then they profiled Crestron-device.&lt;/P&gt;
&lt;P&gt;1- allowed crestron to get full access to the network or any level access ,assuming that we have it in production and need to access internal resources, its done via policy set if endpoint policy=crestron device&lt;/P&gt;
&lt;P&gt;2- changed my macbook pro mac address to 00:10:7F:00:12:34 with command sudo ifconfig en3 ether 00:10:7F:00:12:34&lt;/P&gt;
&lt;P&gt;2- started endpoint debug&lt;/P&gt;
&lt;P&gt;3- no shutdown the access port&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;dhcp probe&lt;/P&gt;
&lt;P&gt;MAC: 00:10:7F:00:12:34&lt;BR /&gt;Attribute:BYODRegistration value:Unknown&lt;BR /&gt;Attribute:DeviceRegistrationStatus value:NotRegistered&lt;BR /&gt;Attribute:EndPointPolicy value:Unknown&lt;BR /&gt;Attribute:EndPointPolicyID value:&lt;BR /&gt;&lt;STRONG&gt;Attribute:EndPointSource value:DHCP Probe&lt;/STRONG&gt;&lt;BR /&gt;Attribute:IdentityGroup value:&lt;BR /&gt;Attribute:IdentityGroupID value:&lt;BR /&gt;Attribute:MACAddress value:00:10:7F:00:12:34&lt;BR /&gt;Attribute:MatchedPolicy value:Unknown&lt;BR /&gt;Attribute:MatchedPolicyID value:&lt;BR /&gt;Attribute:NmapSubnetScanID value:0&lt;BR /&gt;&lt;STRONG&gt;Attribute:OUI value:CRESTRON ELECTRONICS, INC.&lt;/STRONG&gt;&lt;BR /&gt;Attribute:PolicyVersion value:0&lt;BR /&gt;Attribute:PortalUser value:&lt;BR /&gt;Attribute:PostureApplicable value:Yes&lt;BR /&gt;Attribute:StaticAssignment value:false&lt;BR /&gt;Attribute:StaticGroupAssignment value:false&lt;BR /&gt;Attribute:Total Certainty Factor value:0&lt;BR /&gt;Attribute:chaddr value:00:10:7f:00:12:34&lt;BR /&gt;Attribute:ciaddr value:0.0.0.0&lt;BR /&gt;Attribute:dhcp-client-identifier value:01:00:10:7f:00:12:34&lt;BR /&gt;Attribute:dhcp-lease-time value:7776000&lt;BR /&gt;Attribute:dhcp-max-message-size value:1500&lt;BR /&gt;Attribute:dhcp-message-type value:DHCPREQUEST&lt;BR /&gt;&lt;STRONG&gt;Attribute:dhcp-parameter-request-list value:1, 121, 3, 6, 15, 119, 252, 95, 44, 46&lt;/STRONG&gt;&lt;BR /&gt;Attribute:dhcp-requested-address value:10.101.234.27&lt;BR /&gt;Attribute:flags value:0x0000&lt;BR /&gt;Attribute:giaddr value:10.101.234.1&lt;BR /&gt;Attribute:hlen value:6&lt;BR /&gt;Attribute:hops value:1&lt;BR /&gt;Attribute:host-name value:Mustafas-MBP&lt;BR /&gt;Attribute:htype value:Ethernet (10Mb)&lt;BR /&gt;Attribute:ip value:10.101.234.27&lt;BR /&gt;Attribute:op value:BOOTREQUEST&lt;BR /&gt;Attribute:secs value:0&lt;BR /&gt;Attribute:tranID value:0x94a74c38&lt;BR /&gt;Attribute:yiaddr value:0.0.0.0&lt;BR /&gt;Attribute:SkipProfiling value:false&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;results:&lt;/P&gt;
&lt;P&gt;Attribute:AAA-Server value:SNS-PSN1&lt;BR /&gt;Attribute:AcsSessionID value:SNS-PSN1/334707989/1080&lt;BR /&gt;Attribute:AuthenticationIdentityStore value:Internal Endpoints&lt;BR /&gt;Attribute:AuthenticationMethod value:Lookup&lt;BR /&gt;Attribute:AuthenticationStatus value:AuthenticationPassed&lt;BR /&gt;Attribute:&lt;STRONG&gt;AuthorizationPolicyMatchedRule value:SNS DATA&lt;/STRONG&gt;&lt;BR /&gt;Attribute:BYODRegistration value:Unknown&lt;BR /&gt;Attribute:CPMSessionID value:0A65EA050000103942F963D8&lt;BR /&gt;Attribute:Called-Station-ID value:E0-D1-73-8E-FA-84&lt;BR /&gt;Attribute:Calling-Station-ID value:00-10-7F-00-12-34&lt;BR /&gt;Attribute:DTLSSupport value:Unknown&lt;BR /&gt;Attribute:DestinationIPAddress value:10.155.76.89&lt;BR /&gt;Attribute:DestinationPort value:1812&lt;BR /&gt;Attribute:Device IP Address value:switch ip removed&lt;BR /&gt;Attribute:Device Type value:Device Type#switch type removed&lt;BR /&gt;Attribute:DeviceRegistrationStatus value:notRegistered&lt;BR /&gt;Attribute:EndPointMACAddress value:00-10-7F-00-12-34&lt;BR /&gt;&lt;STRONG&gt;Attribute:EndPointMatchedProfile value:Crestron-Device&lt;/STRONG&gt;&lt;BR /&gt;Attribute:EndPointPolicy value:211fce40-8c00-11e6-996c-525400b48521&lt;BR /&gt;Attribute:EndPointPolicyID value:&lt;BR /&gt;Attribute:EndPointSource value:RADIUS Probe&lt;BR /&gt;Attribute:FailureReason value:-&lt;BR /&gt;Attribute:Framed-IP-Address value:10.101.234.27&lt;BR /&gt;Attribute:Framed-MTU value:1500&lt;BR /&gt;Attribute:IPSEC value:IPSEC#Is IPSEC Device#No&lt;BR /&gt;Attribute:ISEPolicySetName value:WIRED_MAB&lt;BR /&gt;Attribute:IdentityGroup value:&lt;BR /&gt;Attribute:IdentityGroupID value:&lt;BR /&gt;Attribute:IdentityPolicyMatchedRule value:INTERNAL_AUTHEN&lt;BR /&gt;Attribute:IdentitySelectionMatchedRule value:INTERNAL_AUTHEN&lt;BR /&gt;Attribute:IsThirdPartyDeviceFlow value:false&lt;BR /&gt;Attribute:Location value:Location#location removed&lt;BR /&gt;Attribute:MACAddress value:00:10:7F:00:12:34&lt;BR /&gt;Attribute:MatchedPolicy value:Unknown&lt;BR /&gt;Attribute:MatchedPolicyID value:&lt;BR /&gt;Attribute:MessageCode value:5200&lt;BR /&gt;Attribute:NAS-IP-Address value:switch ip removed&lt;BR /&gt;Attribute:NAS-Port value:50104&lt;BR /&gt;Attribute:NAS-Port-Id value:GigabitEthernet1/0/4&lt;BR /&gt;Attribute:NAS-Port-Type value:Ethernet&lt;BR /&gt;&lt;STRONG&gt;Attribute:Name value:Endpoint Identity Groups:Profiled&lt;/STRONG&gt;&lt;BR /&gt;Attribute:Network Device Profile value:Cisco&lt;BR /&gt;Attribute:NetworkDeviceGroups value:Location#location removed, Device Type#switch type removed, IPSEC#Is IPSEC Device#No&lt;BR /&gt;Attribute:NetworkDeviceName value:Mustafa_ISE_3850&lt;BR /&gt;Attribute:NetworkDeviceProfileId value:b0699505-3150-4215-a80e-6753d45bf56c&lt;BR /&gt;Attribute:NetworkDeviceProfileName value:Cisco&lt;BR /&gt;Attribute:NmapSubnetScanID value:0&lt;BR /&gt;&lt;STRONG&gt;Attribute:OUI value:CRESTRON ELECTRONICS, INC.&lt;/STRONG&gt;&lt;BR /&gt;Attribute:OriginalUserName value:00107f001234&lt;BR /&gt;Attribute:PolicyVersion value:0&lt;BR /&gt;Attribute:PortalUser value:&lt;BR /&gt;Attribute:PostureApplicable value:Yes&lt;BR /&gt;Attribute:PostureAssessmentStatus value:NotApplicable&lt;BR /&gt;Attribute:RadiusFlowType value:WiredMAB&lt;BR /&gt;Attribute:RequestLatency value:40&lt;BR /&gt;Attribute:Response value:{UserName=00:10:7F:00:12:34; User-Name=00-10-7F-00-12-34; State=ReauthSession:0A65EA050000103942F963D8; Class=CACS:0A65EA050000103942F963D8:SNS-PSN1/334707989/1080; cisco-av-pair=ACS:CiscoSecure-Defined-ACL=#ACSACL#-IP-PERMIT-ALL-TRAFFIC-5c088efb; cisco-av-pair=profile-name=Crestron-Device; LicenseTypes=1539; }&lt;BR /&gt;Attribute:SSID value:E0-D1-73-8E-FA-84&lt;BR /&gt;Attribute:SelectedAccessService value:SNS-PROTOCOLS&lt;BR /&gt;Attribute:SelectedAuthenticationIdentityStores value:Internal Endpoints&lt;BR /&gt;&lt;STRONG&gt;Attribute:SelectedAuthorizationProfiles value:Full Access&lt;/STRONG&gt;&lt;BR /&gt;Attribute:Service-Type value:Call Check&lt;BR /&gt;Attribute:StaticAssignment value:false&lt;BR /&gt;Attribute:StaticGroupAssignment value:false&lt;BR /&gt;Attribute:StepData value:5= Normalised Radius.RadiusFlowType, 7=Internal Endpoints, 14= EndPoints.EndPointPolicy&lt;BR /&gt;Attribute:Total Certainty Factor value:0&lt;BR /&gt;Attribute:UseCase value:Host Lookup&lt;BR /&gt;Attribute:User-Name value:00107f001234&lt;BR /&gt;Attribute:UserName value:00-10-7F-00-12-34&lt;BR /&gt;Attribute:UserType value:Host&lt;BR /&gt;Attribute:allowEasyWiredSession value:false&lt;BR /&gt;Attribute:cisco-av-pair value:service-type=Call Check, audit-session-id=0A65EA050000103942F963D8, method=mab&lt;BR /&gt;Attribute:ip value:10.101.234.27&lt;BR /&gt;Attribute:SkipProfiling value:false&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;as you can see the OUI is Crestron and its getting that access level which is full in my case,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the only attribute from apple OSX (client side) is the dhcp-parameter-request-list value:1, 121, 3, 6, 15, 119, 252, 95, 44, 46 so i went ahead and and modify apple-device profile to check for this value and to increase the certainty by 20 to override the crestron certainty of 5.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is the result&lt;/P&gt;
&lt;P&gt;MAC: 00:10:7F:00:12:34&lt;BR /&gt;Attribute:AAA-Server value:SNS-PSN1&lt;BR /&gt;Attribute:AuthenticationIdentityStore value:Internal Endpoints&lt;BR /&gt;Attribute:AuthenticationMethod value:Lookup&lt;BR /&gt;&lt;STRONG&gt;Attribute:AuthorizationPolicyMatchedRule value:NON-SNS-APPLE_NON-SNS-USER(GUEST)&lt;/STRONG&gt;&lt;BR /&gt;Attribute:BYODRegistration value:Unknown&lt;BR /&gt;Attribute:CacheUpdateTime value:1546972431455&lt;BR /&gt;Attribute:Calling-Station-ID value:00-10-7F-00-12-34&lt;BR /&gt;Attribute:CreateTime value:1546972400212&lt;BR /&gt;Attribute:DTLSSupport value:Unknown&lt;BR /&gt;Attribute:DestinationIPAddress value:10.150.67.89&lt;BR /&gt;Attribute:Device Identifier value:&lt;BR /&gt;Attribute:Device Type value:Device Type#switch type removed&lt;BR /&gt;Attribute:DeviceRegistrationStatus value:NotRegistered&lt;BR /&gt;&lt;STRONG&gt;Attribute:EndPointPolicy value:Apple-MacBook&lt;/STRONG&gt;&lt;BR /&gt;Attribute:EndPointPolicyID value:09c71730-8c00-11e6-996c-525400b48521&lt;BR /&gt;Attribute:EndPointProfilerServer value:SNS-PSN1.my.place.net&lt;BR /&gt;Attribute:EndPointSource value:RADIUS Probe&lt;BR /&gt;Attribute:FailureReason value:-&lt;BR /&gt;Attribute:FirstCollection value:1546972399878&lt;BR /&gt;Attribute:Framed-IP-Address value:10.101.234.27&lt;BR /&gt;Attribute:IdentityGroup value:Profiled&lt;BR /&gt;Attribute:IdentityGroupID value:aa10ae00-8bff-11e6-996c-525400b48521&lt;BR /&gt;Attribute:LastActivity value:1546972430885&lt;BR /&gt;Attribute:LastNmapScanTime value:0&lt;BR /&gt;Attribute:Location value:Location#location removed&lt;BR /&gt;Attribute:MACAddress value:00:10:7F:00:12:34&lt;BR /&gt;Attribute:MDMServerID value:&lt;BR /&gt;&lt;STRONG&gt;Attribute:MatchedPolicy value:Apple-MacBook&lt;/STRONG&gt;&lt;BR /&gt;Attribute:MatchedPolicyID value:09c71730-8c00-11e6-996c-525400b48521&lt;BR /&gt;Attribute:MessageCode value:3000&lt;BR /&gt;Attribute:NAS-IP-Address value:10.101.234.5&lt;BR /&gt;Attribute:NAS-Port-Id value:GigabitEthernet1/0/4&lt;BR /&gt;Attribute:NAS-Port-Type value:Ethernet&lt;BR /&gt;Attribute:NetworkDeviceName value:Mustafa_ISE_3850&lt;BR /&gt;Attribute:NmapScanCount value:0&lt;BR /&gt;Attribute:NmapSubnetScanID value:0&lt;BR /&gt;&lt;STRONG&gt;Attribute:OUI value:CRESTRON ELECTRONICS, INC.&lt;/STRONG&gt;&lt;BR /&gt;Attribute:PhoneID value:&lt;BR /&gt;Attribute:PolicyVersion value:12&lt;BR /&gt;Attribute:PortalUser value:&lt;BR /&gt;Attribute:PostureApplicable value:Yes&lt;BR /&gt;Attribute:RegistrationTimeStamp value:0&lt;BR /&gt;Attribute:SSID value:E0-D1-73-8E-FA-84&lt;BR /&gt;&lt;STRONG&gt;Attribute:SelectedAuthorizationProfiles value:SNS GUEST&lt;/STRONG&gt;&lt;BR /&gt;Attribute:StaticAssignment value:false&lt;BR /&gt;Attribute:StaticGroupAssignment value:false&lt;BR /&gt;Attribute:TimeToProfile value:315&lt;BR /&gt;Attribute:Total Certainty Factor value:30&lt;BR /&gt;Attribute:UniqueSubjectID value:&lt;BR /&gt;Attribute:UpdateTime value:0&lt;BR /&gt;Attribute:User-Name value:00107f001234&lt;BR /&gt;Attribute:UserName value:00-10-7F-00-12-34&lt;BR /&gt;Attribute:UserType value:Host&lt;BR /&gt;Attribute:ciaddr value:0.0.0.0&lt;BR /&gt;Attribute:dhcp-parameter-request-list value:1, 121, 3, 6, 15, 119, 252, 95, 44, 46&lt;BR /&gt;Attribute:dhcp-requested-address value:10.101.234.27&lt;BR /&gt;Attribute:host-name value:Mustafas-MBP&lt;BR /&gt;Attribute:ip value:10.101.234.27&lt;BR /&gt;Attribute:SkipProfiling value:false&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;from the results we saw OS-X profiled successfully as as apple-device regardless of the user's mac spoofing attempt, Cisco released Parameter Request List Value&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/116235-configure-ise-00.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/116235-configure-ise-00.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;but my macbook Parameter wasn't part of the list, it look like the list is dated&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;now i have few questions&lt;/P&gt;
&lt;P&gt;- will this attribute change or vary from model/OS release to another? if yes, how can we make sure we have the latest Parameter? where it can be found Cisco ISE doc or Apple site?&lt;/P&gt;
&lt;P&gt;- is there any other attribute we can count on that is hard solid and will never change?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;please understand those macbook devices belongs to the guests so i cant install any clients/application on them and we dont have access to&amp;nbsp;their hostname, OS-X version nor model, and for crestron and other profile which i'm not willing to modify to accommodate the apple-devices because the number of profiles are big and not sure if/when Cisco will update one of their provided profile, looking for solution from apple-device profile side.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;FYI: This is not an issue with Windows as windows have many attributes that ISE capture, so changing mac addresses wont matter(if you are using the default profiles) and no changes, no sure and about linux but its in the scope after apple-devices issue resolved.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Mustafa&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 08:53:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-apple-device-profile/m-p/3775392#M541912</guid>
      <dc:creator>mustafa83</dc:creator>
      <dc:date>2019-03-11T08:53:38Z</dc:date>
    </item>
  </channel>
</rss>

